Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
320e60c9 by Salvatore Bonaccorso at 2026-08-16T07:59:37+02:00
Process some NFUs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -11,27 +11,27 @@ CVE-2026-73631 (Exposure of data element to wrong session 
vulnerability in the J
        - libstruts1.2-java <removed>
        NOTE: https://cwiki.apache.org/confluence/display/WW/S2-070
 CVE-2026-19906 (A weakness has been identified in pkp pkp-lib 
3.3.0/3.4.0/3.5.0. This  ...)
-       TODO: check
+       NOT-FOR-US: pkp-lib
 CVE-2026-19905 (A weakness has been identified in Jinher OA 1.0. Impacted is 
an unknow ...)
-       TODO: check
+       NOT-FOR-US: Jinher OA
 CVE-2026-19904 (A vulnerability was found in SourceCodester Online Book Store 
System 1 ...)
        NOT-FOR-US: SourceCodester
 CVE-2026-19903 (A vulnerability has been found in SourceCodester Online 
Clothing Store ...)
        NOT-FOR-US: SourceCodester
 CVE-2026-19901 (A security flaw has been discovered in LB-LINK X-PRO 
1.0.22-20231206.  ...)
-       TODO: check
+       NOT-FOR-US: LB-LINK
 CVE-2026-19900 (A vulnerability was identified in LB-LINK X-PRO 
1.0.22-20231206. The i ...)
-       TODO: check
+       NOT-FOR-US: LB-LINK
 CVE-2026-19899 (A vulnerability was determined in SourceCodester Class and 
Exam Timeta ...)
        NOT-FOR-US: SourceCodester
 CVE-2026-19898 (A vulnerability was found in VictoriaMetrics up to 1.146.0. 
Impacted i ...)
-       TODO: check
+       NOT-FOR-US: VictoriaMetrics
 CVE-2026-19897 (A vulnerability has been found in mangroup dtale up to 3.22.0. 
This is ...)
-       TODO: check
+       NOT-FOR-US: mangroup dtale
 CVE-2026-19896 (A flaw has been found in mangroup dtale up to 3.22.0. This 
vulnerabili ...)
-       TODO: check
+       NOT-FOR-US: mangroup dtale
 CVE-2026-19895 (A vulnerability was detected in opensourcepos Open Source 
Point of Sal ...)
-       TODO: check
+       NOT-FOR-US: opensourcepos Open Source Point of Sale
 CVE-2026-19894 (A security flaw has been discovered in itsourcecode Hospital 
Managemen ...)
        NOT-FOR-US: itsourcecode System
 CVE-2026-19893 (A vulnerability was identified in D-Link DIR-842 2.01.B04. 
This impact ...)
@@ -674,11 +674,11 @@ CVE-2026-34492 (External control of file name or path 
vulnerability in Johnson C
 CVE-2026-27871 (Cwe-327 Use of a Broken or Risky Cryptographic Algorithm 
vulnerability ...)
        NOT-FOR-US: Johnson Controls
 CVE-2026-19910 (PAX Technology Q80 Application Installer Signature 
Verification Bypass ...)
-       TODO: check
+       NOT-FOR-US: PAX Technology Q80 Application Installer
 CVE-2026-19909 (PAX Technology Q80 AIP File Parsing Link Following Remote Code 
Executi ...)
-       TODO: check
+       NOT-FOR-US: PAX Technology Q80
 CVE-2026-19908 (PAX Technology Q80 XCB Daemon Missing Authentication 
Vulnerability. Th ...)
-       TODO: check
+       NOT-FOR-US: PAX Technology Q80
 CVE-2026-18932
        REJECTED
 CVE-2026-18807 (The ECS  WordPress plugin before 4.3.8 does not have 
capability or own ...)
@@ -4751,13 +4751,13 @@ CVE-2026-49986 (The Cortex MCP server 
(`neuro-cortex-memory`), a cross-platform
 CVE-2026-49826 (Concourse is a container-based automation system written in 
Go. Prior  ...)
        NOT-FOR-US: Concourse
 CVE-2026-49457 (erlang_quic is a pure Erlang QUIC implementation. Prior to 
version 1.4 ...)
-       TODO: check
+       NOT-FOR-US: erlang_quic
 CVE-2026-49282 (Capstone is a disassembly framework. Prior to version 
6.0.0-Alpha9, Ca ...)
        TODO: check
 CVE-2026-49263 (Capstone is a disassembly framework. Prior to version 
6.0.0-Alpha9, Ca ...)
        TODO: check
 CVE-2026-48528 (Metacat is data repository software that helps researchers 
preserve, s ...)
-       TODO: check
+       NOT-FOR-US: Metacat
 CVE-2026-46603 (VP8L decoding in golang.org/x/image/vp8l can allocate an 
excessive amo ...)
        TODO: check
 CVE-2026-46439 (compliance-trestle is a tooling platform for managing 
compliance as co ...)
@@ -4773,9 +4773,9 @@ CVE-2026-19880 (Path-traversal vulnerability in QOS.CH 
Sarl Logback-classic on J
 CVE-2026-19879 (A flaw was found in Undertow, an HTTP server, within its HTTP 
response ...)
        TODO: check
 CVE-2026-19871 (Use of Hard-coded Credentials in the human resources component 
in Rosk ...)
-       TODO: check
+       NOT-FOR-US: Roskus Prospero Flow CRM
 CVE-2026-19870 (Authorization Bypass Through User-Controlled Key in the 
payroll module ...)
-       TODO: check
+       NOT-FOR-US: Roskus Prospero Flow CRM
 CVE-2026-19847 (A security flaw has been discovered in TOTOLINK A800R 
4.1.2cu.5137_B20 ...)
        NOT-FOR-US: TOTOLINK
 CVE-2026-19846 (A vulnerability was identified in TOTOLINK A800R 
4.1.2cu.5137_B2020073 ...)
@@ -4801,13 +4801,13 @@ CVE-2026-19834 (A vulnerability was determined in 
Webkul Bagisto up to 2.4.4. Af
 CVE-2026-19830 (A vulnerability was found in TRENDnet TEW-816DRM 
GURNC4.OT182B-C-TN-R1 ...)
        NOT-FOR-US: TRENDnet
 CVE-2026-19829 (A security flaw has been discovered in 648540858 
wvp-GB28181-pro 2.7.4 ...)
-       TODO: check
+       NOT-FOR-US: 648540858 wvp-GB28181-pro
 CVE-2026-19828 (A vulnerability was identified in 648540858 wvp-GB28181-pro 
2.7.4-2026 ...)
-       TODO: check
+       NOT-FOR-US: 648540858 wvp-GB28181-pro
 CVE-2026-19827 (A flaw has been found in alldatacenter alldata up to 0.6.8. 
This impac ...)
-       TODO: check
+       NOT-FOR-US: alldatacenter alldata
 CVE-2026-19826 (A vulnerability was detected in alldatacenter alldata up to 
0.6.8. Thi ...)
-       TODO: check
+       NOT-FOR-US: alldatacenter alldata
 CVE-2026-19825 (A security vulnerability has been detected in SourceCodester 
Simple Cl ...)
        NOT-FOR-US: SourceCodester
 CVE-2026-19824 (A weakness has been identified in Tenda W20E 
15.11.0.6(1068_1546_841)_ ...)
@@ -5134,9 +5134,9 @@ CVE-2026-49096 (Uncaught Exception (CWE-248) in Kibana 
Cases can lead to denial
 CVE-2026-49089 (Allocation of Resources Without Limits or Throttling (CWE-770) 
in Kiba ...)
        TODO: check
 CVE-2026-45774 (compliance-trestle is a tooling platform for managing 
compliance as co ...)
-       TODO: check
+       NOT-FOR-US: compliance-trestle
 CVE-2026-45725 (compliance-trestle is a tooling platform for managing 
compliance as co ...)
-       TODO: check
+       NOT-FOR-US: compliance-trestle
 CVE-2026-3883
        REJECTED
 CVE-2026-19811 (A security flaw has been discovered in TOTOLINK A800R 
4.1.2cu.5137_B20 ...)
@@ -5154,39 +5154,39 @@ CVE-2026-19788 (A vulnerability was found in Tenda 
AC1206 15.03.06.23_multi_TD01
 CVE-2026-19787 (A vulnerability was determined in SourceCodester Air Cargo 
Management  ...)
        NOT-FOR-US: SourceCodester
 CVE-2026-19786 (A vulnerability was found in francoisjacquet RosarioSIS up to 
12.8. Th ...)
-       TODO: check
+       NOT-FOR-US: francoisjacquet RosarioSIS
 CVE-2026-19785 (A vulnerability has been found in francoisjacquet RosarioSIS 
up to 12. ...)
-       TODO: check
+       NOT-FOR-US: francoisjacquet RosarioSIS
 CVE-2026-19784 (A flaw has been found in francoisjacquet RosarioSIS up to 
12.8. This a ...)
-       TODO: check
+       NOT-FOR-US: francoisjacquet RosarioSIS
 CVE-2026-19771 (A vulnerability was identified in Baicells EG3661M 
BaiCE_BQ6_2.0.5.3_N ...)
-       TODO: check
+       NOT-FOR-US: Baicells EG3661M
 CVE-2026-19770 (A vulnerability was identified in feedmob fm-mcp-servers 
0.0.3. Affect ...)
-       TODO: check
+       NOT-FOR-US: feedmob fm-mcp-servers
 CVE-2026-19767 (A weakness has been identified in itsourcecode Hospital 
Management Sys ...)
        NOT-FOR-US: itsourcecode System
 CVE-2026-19765 (A security flaw has been discovered in eyaushev 
swagger-testcase-mcp 5 ...)
-       TODO: check
+       NOT-FOR-US: eyaushev swagger-testcase-mcp
 CVE-2026-19764 (A vulnerability was identified in Raisecom Communication 
Command and D ...)
-       TODO: check
+       NOT-FOR-US: Raisecom Communication Command and Dispatch Management 
Platform
 CVE-2026-19763 (A vulnerability was determined in DTStack Taier 1.4.0. 
Affected by thi ...)
-       TODO: check
+       NOT-FOR-US: DTStack Taier
 CVE-2026-19762 (A vulnerability was found in DTStack Taier 1.4.0. Affected by 
this vul ...)
-       TODO: check
+       NOT-FOR-US: DTStack Taier
 CVE-2026-19761 (A vulnerability has been found in DTStack Taier 1.4.0. 
Affected is the ...)
-       TODO: check
+       NOT-FOR-US: DTStack Taier
 CVE-2026-19758 (A vulnerability was determined in dromara lamp-cloud up to 
5.10.0. Thi ...)
-       TODO: check
+       NOT-FOR-US: dromara lamp-cloud
 CVE-2026-19757 (A vulnerability was found in Dromara lamp-cloud up to 5.10.0. 
This vul ...)
-       TODO: check
+       NOT-FOR-US: Dromara lamp-cloud
 CVE-2026-19756 (A vulnerability has been found in Dromara lamp-cloud up to 
5.10.0. Thi ...)
-       TODO: check
+       NOT-FOR-US: Dromara lamp-cloud
 CVE-2026-19753 (A vulnerability was detected in Model Context Protocol 
mcp-rdf-explore ...)
-       TODO: check
+       NOT-FOR-US: Model Context Protocol mcp-rdf-explorer
 CVE-2026-19752 (A vulnerability was found in EnzoVezzaro mcp-dominican-layer 
up to 39d ...)
-       TODO: check
+       NOT-FOR-US: EnzoVezzaro mcp-dominican-layer
 CVE-2026-19751 (A flaw has been found in EnzoVezzaro mcp-dominican-layer up to 
39dd373 ...)
-       TODO: check
+       NOT-FOR-US: EnzoVezzaro mcp-dominican-layer
 CVE-2026-19750 (A flaw has been found in Tenda CH, CP and TX3 
V21.x/V22.x/V25.x/V26.x/ ...)
        NOT-FOR-US: Tenda
 CVE-2026-19749 (A vulnerability was detected in Tenda CH7, CH7G, CH10, CP3, 
CP3 Pro, C ...)
@@ -5196,9 +5196,9 @@ CVE-2026-19748 (A security vulnerability has been 
detected in Tenda CH7, CH7G, C
 CVE-2026-19747 (A weakness has been identified in Tenda CH7, CH7G, CH10, CP3, 
CP3 Pro, ...)
        NOT-FOR-US: Tenda
 CVE-2026-19746 (A vulnerability has been found in Calix GigaSpire 26.1.0. The 
affected ...)
-       TODO: check
+       NOT-FOR-US: Calix GigaSpire
 CVE-2026-19745 (A flaw has been found in Calix GigaSpire 26.1.0. Impacted is 
an unknow ...)
-       TODO: check
+       NOT-FOR-US: Calix GigaSpire
 CVE-2026-19617 (A flaw was found in libdm. A local attacker could craft a 
malicious Lo ...)
        TODO: check
 CVE-2026-19483 (IBM Storage Scale 5.2.3.0 through 5.2.3.8, and 6.0.0.0 through 
6.0.1.0 ...)
@@ -6080,9 +6080,9 @@ CVE-2026-23603 (Blind SSRF in OAuth2 avatar 
synchronization via unvalidated OIDC
 CVE-2026-21832 (HCL AION is affected by a vulnerability where indirect prompt 
injectio ...)
        NOT-FOR-US: HCL
 CVE-2026-19744 (Cross-site Scripting in the Markdown renderer in maalfer 
Pentestify be ...)
-       TODO: check
+       NOT-FOR-US: maalfer Pentestify
 CVE-2026-19734 (Missing Authorization and Authorization Bypass Through 
User-Controlled ...)
-       TODO: check
+       NOT-FOR-US: Roskus Prospero Flow CRM
 CVE-2026-19730 (The 'podman quadlet install --replace' command opens the 
existing dest ...)
        TODO: check
 CVE-2026-19716 (Stored Cross-site Scripting (CWE-79) in the user management 
component  ...)
@@ -6662,17 +6662,17 @@ CVE-2026-49473 
(@cedar-policy/authorization-for-expressjs is an open-source Expr
 CVE-2026-49466 (Draft List is a WordPress plugin to manage and promote 
unpublished con ...)
        NOT-FOR-US: WordPress plugin
 CVE-2026-48791 (sigstore-java is a sigstore java client for interacting with 
sigstore  ...)
-       TODO: check
+       NOT-FOR-US: sigstore-java
 CVE-2026-47718 (FUXA is a web-based Process Visualization 
(SCADA/HMI/Dashboard) softwa ...)
-       TODO: check
+       NOT-FOR-US: FUXA
 CVE-2026-47717 (FUXA is a web-based Process Visualization 
(SCADA/HMI/Dashboard) softwa ...)
-       TODO: check
+       NOT-FOR-US: FUXA
 CVE-2026-46731 (Dell Display and Peripheral Manager (DDPM Windows), versions 
prior to  ...)
        NOT-FOR-US: Dell / EMC
 CVE-2026-46688 (The Meeting Room Booking System (MRBS) is a PHP-based 
application for  ...)
-       TODO: check
+       NOT-FOR-US: Meeting Room Booking System (MRBS)
 CVE-2026-46382 (The Meeting Room Booking System (MRBS) is a PHP-based 
application for  ...)
-       TODO: check
+       NOT-FOR-US: Meeting Room Booking System (MRBS)
 CVE-2026-3835 (The Prevent Direct Access \u2013 Protect WordPress Files plugin 
for Wo ...)
        NOT-FOR-US: WordPress plugin
 CVE-2026-19657 (ScadaLTS 2.7.8.1reflects user-supplied input into an HTML 
response wit ...)
@@ -7127,7 +7127,7 @@ CVE-2026-49467 (Pingvin Share X is a secure and easy 
self-hosted file sharing pl
 CVE-2026-49349 (regclient is a Docker and OCI Registry Client in Go. Prior to 
version  ...)
        TODO: check
 CVE-2026-49262 (In the Aimeos Pagible content management system prior to 
version 0.10. ...)
-       TODO: check
+       NOT-FOR-US: Aimeos Pagible content management system
 CVE-2026-48554 (Nagios Core before 4.5.14 and Nagios XI before 2026R1.7 are 
vulnerable ...)
        TODO: check
 CVE-2026-48553 (Nagios Core before 4.5.13 and Nagios XI before 2026R1.5 are 
vulnerable ...)
@@ -7157,9 +7157,9 @@ CVE-2026-47227 (Admidio is an open-source user management 
solution. `modules/cat
 CVE-2026-47226 (Admidio is an open-source user management solution. Prior to 
version 5 ...)
        NOT-FOR-US: Admidio
 CVE-2026-44741 (Pimcore's Admin Classic Bundle provides a Backend UI for 
Pimcore. Vers ...)
-       TODO: check
+       NOT-FOR-US: Pimcore
 CVE-2026-42018 (JFrog Artifactory could return an internal anonymous-user 
token to an  ...)
-       TODO: check
+       NOT-FOR-US: JFrog Artifactory
 CVE-2026-26035 (An Improper Authentication vulnerability [CWE-287] 
vulnerability in Fo ...)
        NOT-FOR-US: Fortinet
 CVE-2026-19548 (Multiple Use-After-Free vulnerabilities were found in the 
add_archive_ ...)
@@ -7596,7 +7596,7 @@ CVE-2026-5917 (libgit2 versions v0.27.0 through v1.9.0 
built with the libssh2 SS
 CVE-2026-55676 (Malcolm is a network traffic analysis tool suite. The 
file-upload comp ...)
        NOT-FOR-US: Malcolm
 CVE-2026-48813 (Flawfinder is a a static analysis tool for finding 
vulnerabilities in  ...)
-       TODO: check
+       NOT-FOR-US: Flawfinder
 CVE-2026-48804 (python-socketio is a Python implementation of the Socket.IO 
realtime c ...)
        TODO: check
 CVE-2026-48765 (TypeBot is a chatbot builder tool. Versions prior to 3.17.0 
allow a lo ...)
@@ -9139,7 +9139,7 @@ CVE-2026-48809 (python-engineio is a Python 
implementation of the Engine.IO real
 CVE-2026-48802 (python-engineio is a Python implementation of the Engine.IO 
realtime c ...)
        TODO: check
 CVE-2026-48790 (Turso CLI is the command line interface (CLI) to the 
open-source datab ...)
-       TODO: check
+       NOT-FOR-US: Turso CLI
 CVE-2026-48771 (ishankportfolio is a portfolio website. Prior to version 
1.0.1, contac ...)
        NOT-FOR-US: ishankportfolio
 CVE-2026-48767 (TypeBot is a chatbot builder tool. Versions prior to 3.17.0 
allow a lo ...)
@@ -9225,9 +9225,9 @@ CVE-2026-48375 (ColdFusion is affected by an Incorrect 
Authorization vulnerabili
 CVE-2026-48362 (ColdFusion is affected by an Improper Neutralization of 
Special Elemen ...)
        NOT-FOR-US: Adobe
 CVE-2026-48056 (Streambert is a cross-platform Electron Desktop App to stream 
and down ...)
-       TODO: check
+       NOT-FOR-US: Streambert
 CVE-2026-48046 (Streambert is a cross-platform Electron Desktop App to stream 
and down ...)
-       TODO: check
+       NOT-FOR-US: Streambert
 CVE-2026-47940 (Lightroom Classic is affected by an Integer Overflow or 
Wraparound vul ...)
        NOT-FOR-US: Adobe
 CVE-2026-47922 (CAI Content Credentials is affected by a Server-Side Request 
Forgery ( ...)
@@ -9245,21 +9245,21 @@ CVE-2026-47285 (Improper neutralization of special 
elements used in a command ('
 CVE-2026-46670 (YesWiki is a wiki system written in PHP. Prior to version 
4.6.4,  an u ...)
        NOT-FOR-US: YesWiki
 CVE-2026-43606 (Observable Timing Discrepancy in the AMD Vitis Libraries ECDSA 
secp256 ...)
-       TODO: check
+       NOT-FOR-US: AMD
 CVE-2026-42976 (Missing authentication for critical function in Windows RPC 
API allows ...)
        NOT-FOR-US: Microsoft
 CVE-2026-42142 (TypeBot is a chatbot builder tool. Prior to version 3.17.0, 
the `handl ...)
-       TODO: check
+       NOT-FOR-US: TypeBot
 CVE-2026-40375 (Missing authorization in Dynamics Business Central allows an 
authorize ...)
        NOT-FOR-US: Microsoft
 CVE-2026-39452 (Protection mechanism failure for some Intel(R) Transfer 
Learning Tool  ...)
-       TODO: check
+       NOT-FOR-US: Intel
 CVE-2026-35502 (Deserialization of untrusted data for some Intel(R) Extension 
for PyTo ...)
-       TODO: check
+       NOT-FOR-US: Intel
 CVE-2026-34635 (is affected by a Use of Hard-coded Cryptographic Key 
vulnerability tha ...)
        NOT-FOR-US: Adobe
 CVE-2026-34175 (Uncontrolled search path for some 
Hardware-Aware-Automated-MachineLear ...)
-       TODO: check
+       NOT-FOR-US: Intel
 CVE-2026-33922 (A path traversal vulnerability was discovered in the Offline 
archives  ...)
        NOT-FOR-US: Nozomi Arc
 CVE-2026-33921 (The Windows installer deployed Npcap leaving its access 
restriction op ...)
@@ -9267,13 +9267,13 @@ CVE-2026-33921 (The Windows installer deployed Npcap 
leaving its access restrict
 CVE-2026-32791 (Untrusted search path for some Intel(R) Performance Counter 
Monitor (I ...)
        NOT-FOR-US: Intel
 CVE-2026-32788 (Uncontrolled search path for some Approximate Bayesian 
Inference Frame ...)
-       TODO: check
+       NOT-FOR-US: Intel
 CVE-2026-32677 (Path traversal for some gaudi-container-runtime before version 
1.24.0  ...)
        NOT-FOR-US: gaudi-container-runtime
 CVE-2026-28757 (Protection mechanism failure for some Intel(R) Workload 
Services Frame ...)
        NOT-FOR-US: Intel
 CVE-2026-28729 (Integer overflow in the UEFI firmware for the Intel(R) Slim 
Bootloader ...)
-       TODO: check
+       NOT-FOR-US: Intel
 CVE-2026-28707 (Protection mechanism failure for some LLM-on-Ray before 
version 1.0 wi ...)
        NOT-FOR-US: Intel
 CVE-2026-28700 (Uncontrolled search path for some EquiTriton before version 
f5ddbb5 wi ...)
@@ -9285,21 +9285,21 @@ CVE-2026-27302 (Adobe Campaign Classic (ACC) is 
affected by an Incorrect Authori
 CVE-2026-25652 (is affected by an Incorrect Authorization vulnerability that 
could res ...)
        NOT-FOR-US: Adobe
 CVE-2026-25194 (Out-of-bounds write in the firmware for the Intel(R) Slim 
Bootloader m ...)
-       TODO: check
+       NOT-FOR-US: Intel
 CVE-2026-24911 (Stack-based buffer overflow for some Intel(R) PROSet/Wireless 
WiFi Sof ...)
        NOT-FOR-US: Intel
 CVE-2026-24693 (Protection mechanism failure for some Intel(R) oneCCL Bindings 
for PyT ...)
-       TODO: check
+       NOT-FOR-US: Intel
 CVE-2026-24099 (Use after free for some Intel(R) PROSet/Wireless WiFi Software 
for Win ...)
        NOT-FOR-US: Intel
 CVE-2026-22887 (Improper buffer restrictions for some Intel(R) PROSet/Wireless 
WiFi So ...)
        NOT-FOR-US: Intel
 CVE-2026-21400 (Protection mechanism failure for some Intel(R) AI Reference 
Models bef ...)
-       TODO: check
+       NOT-FOR-US: Intel
 CVE-2026-21399 (Heap-based buffer overflow for the Intel(R) Open Volume Kernel 
Library ...)
-       TODO: check
+       NOT-FOR-US: Intel
 CVE-2026-21387 (Protection mechanism failure for some Intel(R) LLM Library for 
PyTorch ...)
-       TODO: check
+       NOT-FOR-US: Intel
 CVE-2026-21279 (is affected by an Improper Input Validation vulnerability that 
could r ...)
        NOT-FOR-US: Adobe
 CVE-2026-21273 (is affected by an Improper Input Validation vulnerability that 
could r ...)
@@ -9313,9 +9313,9 @@ CVE-2026-20908 (Time-of-check time-of-use race condition 
for the Intel(R) NPU Dr
 CVE-2026-20906 (Protection mechanism failure for some Intel(R) Neural 
Compressor softw ...)
        NOT-FOR-US: Intel
 CVE-2026-20903 (Protection mechanism failure for some Intel(R) AI Containers 
before ve ...)
-       TODO: check
+       NOT-FOR-US: Intel
 CVE-2026-20898 (Improper access control in the firmware for some in Alias 
Checking Tru ...)
-       TODO: check
+       NOT-FOR-US: Intel
 CVE-2026-20891 (Improper authentication for some Intel(R) PROSet/Wireless WiFi 
Softwar ...)
        NOT-FOR-US: Intel
 CVE-2026-20890 (Improper privilege management for some Intel(R) 
PROSet/Wireless WiFi S ...)
@@ -9323,11 +9323,11 @@ CVE-2026-20890 (Improper privilege management for some 
Intel(R) PROSet/Wireless
 CVE-2026-20886 (Out-of-bounds write for some Intel(R) PROSet/Wireless WiFi 
Software fo ...)
        NOT-FOR-US: Intel
 CVE-2026-20885 (Improper authentication in the Intel(R) TDX module for some 
Intel(R) p ...)
-       TODO: check
+       NOT-FOR-US: Intel
 CVE-2026-20878 (Null pointer dereference for some Intel(R) PROSet/Wireless 
WiFi Softwa ...)
        NOT-FOR-US: Intel
 CVE-2026-20799 (Untrusted search path for some Battery Life Diagnostic Tool 
software b ...)
-       TODO: check
+       NOT-FOR-US: Intel
 CVE-2026-20795 (Improper buffer restrictions for some Intel(R) PROSet/Wireless 
WiFi So ...)
        NOT-FOR-US: Intel
 CVE-2026-20789 (Improper access control for some Intel(R) PROSet/Wireless WiFi 
Softwar ...)
@@ -9345,9 +9345,9 @@ CVE-2026-20778 (Out-of-bounds read for some Intel(R) 
PROSet/Wireless WiFi Softwa
 CVE-2026-20776 (Improper conditions check for some Intel(R) PROSet/Wireless 
WiFi Softw ...)
        TODO: check
 CVE-2026-20775 (Uncaught exception for some Intel(R) TDX modules within Ring 
0: Trust  ...)
-       TODO: check
+       NOT-FOR-US: Intel
 CVE-2026-20770 (Protection mechanism failure for some Cluster Management 
Toolkit for K ...)
-       TODO: check
+       NOT-FOR-US: Intel
 CVE-2026-20769 (Improper conditions check for the Intel(R) NPU Driver for all 
versions ...)
        TODO: check
 CVE-2026-20765 (Incorrect comparison for some Intel(R) TDX Guest software 
before versi ...)
@@ -9371,7 +9371,7 @@ CVE-2026-20739 (Improper conditions check for some 
Intel(R) PROSet/Wireless WiFi
 CVE-2026-20737 (Exposure of sensitive information to an unauthorized actor for 
some In ...)
        NOT-FOR-US: Intel
 CVE-2026-20734 (Improper initialization in some firmware for some Intel(R) 
Active Mana ...)
-       TODO: check
+       NOT-FOR-US: Intel
 CVE-2026-20731 (Improper buffer restrictions for the Intel(R) NPU Driver for 
all versi ...)
        TODO: check
 CVE-2026-20728 (Protection mechanism failure for some Intel Extension for 
TensorFlow s ...)
@@ -9379,17 +9379,17 @@ CVE-2026-20728 (Protection mechanism failure for some 
Intel Extension for Tensor
 CVE-2026-20727 (Null pointer dereference for some Intel(R) PROSet/Wireless 
WiFi Softwa ...)
        NOT-FOR-US: Intel
 CVE-2026-20715 (Improper input validation in some firmware for some Intel(R) 
Active Ma ...)
-       TODO: check
+       NOT-FOR-US: Intel
 CVE-2026-20712 (Incomplete cleanup in some UEFI firmware for some Intel(R) 
reference p ...)
        NOT-FOR-US: Intel
 CVE-2026-20708 (Insertion of sensitive information into log file in the 
subsystem for  ...)
-       TODO: check
+       NOT-FOR-US: Intel
 CVE-2026-20705 (Insecure storage of sensitive information in the Intel(R) TDX 
module f ...)
-       TODO: check
+       NOT-FOR-US: Intel
 CVE-2026-20702 (Protection mechanism failure for some Intel(R) Data Center 
Attestation ...)
-       TODO: check
+       NOT-FOR-US: Intel
 CVE-2026-20349 (A vulnerability in the Remote Access SSL VPN service for Cisco 
Secure  ...)
-       TODO: check
+       NOT-FOR-US: Cisco
 CVE-2026-19546 (A flaw was found in DBI. This is a fix for a partial fix for 
CVE-2026- ...)
        - libdbi-perl <not-affected> (Red Hat-specific backport issue)
        NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2513963
@@ -10461,13 +10461,13 @@ CVE-2026-55814 (Missing Authentication in Apache 
Ranger Download APIs on version
 CVE-2026-55799 (Remote Code Execution Vulnerability in 
GraalScriptEngineCreator in Apa ...)
        NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-48159 (use-reducer-async is a React useReducer with async actions. 
Between 20 ...)
-       TODO: check
+       NOT-FOR-US: use-reducer-async
 CVE-2026-48158 (use-context-selector is a React useContextSelector hook in 
userland Be ...)
-       TODO: check
+       NOT-FOR-US: use-context-selector
 CVE-2026-48048 (XWiki Platform is a generic wiki platform. XWiki discovered 
that the p ...)
        NOT-FOR-US: XWiki
 CVE-2026-47754 (Metacat is data repository software that helps researchers 
preserve, s ...)
-       TODO: check
+       NOT-FOR-US: Metacat
 CVE-2026-44630 (Improper validation of length fields in the Apache IoTDB RPC 
service m ...)
        NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-44416 (Remote Code Execution via Arbitrary Class Instantiation 
inplugin-schem ...)



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/320e60c9e8765e3e587a8286a9bf7eb9837e84b8

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/320e60c9e8765e3e587a8286a9bf7eb9837e84b8
You're receiving this email because of your account on salsa.debian.org. Manage 
all notifications: https://salsa.debian.org/-/profile/notifications | Help: 
https://salsa.debian.org/help


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to